Blog
Short, factual notes on the compliance and technology questions our clients ask — written as questions and answers, with the rule, the clock, or the artifact named directly.
These posts summarise how requirements apply to the technology a regulated firm runs. They are not legal advice. For the full reference pages, see compliance frameworks and industries we serve.
Regulation S-P Notification Clocks: the 30-Day Customer Notice and the 72-Hour Vendor Notice
What the 30-day customer notification and the 72-hour service-provider notification under Regulation S-P require of an RIA, when each clock starts, and what belongs in the file.
Read the postHIPAA for Technology Vendors and MSPs: Business Associate Status, BAAs, Access, and Logging
When an IT provider becomes a HIPAA business associate, what the business associate agreement has to cover, and how the access-control and audit-control standards apply to the vendor's own tooling.
Read the post